5 ms·
Trivy: A scanner for vulnerabilities in containers, file systems, and Git repos
- jamesfinlayson 5y agoIs this what powers AquaSec?
- cpressland 5y agoYes, we use AquaSec and it’s absolutely the same engine. Trivy is so good we were tempted to drop AquaSec entirely as we only use it in our CI and this covers our requirements.
- zxcvbn4038 5y agoI’ve had a great experience with Trivy, very solid tool, very easy to write automation around.
- smegcicle 5y ago> Trivy (tri pronounced like trigger, vy pronounced like envy) That's not the first thing that comes to mind.. but anyway what's the catch, does it rely on a more complete IaC-style deployment than you often find?
- efrecon 5y agoTrivy is good. It comes bundled with the harbor docker registry, meaning you get security analysis of your images and provide for some level of security as you can prevent pulling critical images (or whatever level you deem necessary).
- Jabihjo 5y agoIt seems that this does the same thing as Anchore. Is there a difference that I'm not seeing? Also, I couldn't find anything for Trivy that gives you a nice web UI like what Snyk does, or did I miss something there as well?
- markuman123 5y agoit's super easy to integrate in every ci/cd pipeline